Blindbandit Platform API v1
Label apps exchange a website session at POST /v1/auth/session. Blindbandit Mobile (/mobile) uses Clerk directly on /api/v1/social/* and /api/v1/livekit/token. API also served at api.mrblindbandit.net. Mobile clients store returned credentials in secure device storage. Refresh tokens rotate after use. Owner operations require separate owner access and recent verification.
Download the current OpenAPI specification
Available operations
- Capability registry (ga|beta|planned)
- Single capability descriptor
- Runtime feature flags merged with capability defaults
- Override a feature flag (admin/owner)
- Public API liveness
- Public mobile configuration
- Exchange an existing website session for a mobile session
- Rotate access and refresh credentials
- Revoke this API session
- Revoke all API sessions for the current account
- Current API authentication status
- Verify a sensitive API session
- Verify an owner API session
- Exchange the dedicated owner master credential
- Mobile owner access status
- Configure or rotate the dedicated owner credential
- Disable mobile owner access and revoke owner credentials
- List owner device sessions
- Revoke one owner device session
- Revoke every mobile owner session
- Integration catalog and safe credential status
- Encrypt and save integration credentials
- Remove saved credentials and keep the integration disabled
- Run a read-only provider connection test
- Disable an integration configuration
- Current account profile
- Update the label display name
- Read notification and accessibility preferences
- Update notification and accessibility preferences
- Native home dashboard
- Update remote app configuration
- Register or update an encrypted device token
- List own devices without raw push tokens
- Update own device preference
- Unregister an owned device
- Send a test to one of the owner’s own devices
- Inspect sanitized push delivery results
- List owned notifications
- Count unread owned notifications
- Mark own notifications as read
- Mark an owned notification as read
- Dismiss an owned notification
- Create an in-app notification for one active account
- List own favorite links
- Save a website shortcut
- Delete an owned shortcut
- Submit a support ticket
- List own support tickets
- Read an owned support ticket
- Submit beta feedback without automatic diagnostics
- Current account activity without security events
- Sanitized security events
- Owner audit history
- Safe platform diagnostics
- Label summary for the current role
- Read permitted earnings records
- Record earnings subject to existing finance permissions
- Read permitted contract metadata
- Read permitted artist profiles
- List existing label accounts
- Invite a label account with an allowed role
- Update an existing label role or account state
- Read a permitted client message thread
- Send a message within a permitted client thread
- Read permitted existing payment information
- Read permitted existing client tasks
- Create a task subject to existing project permissions
- Read existing announcements allowed for this account
- Create a label announcement
- Search existing label records with role filters
- Discover available label workspace modules and field schemas
- Read an existing workspace subject to its role policy
- Create a validated workspace record
- Update a workspace record using its revision
- Read existing release plans subject to label permissions
- Create a validated release plan
- Update a release plan using its current revision
- List background tools and processor readiness
- Reserve private media storage (1 GB per account)
- Stream reserved bytes with exact Content-Type and Content-Length
- List owned private media
- Read owned media metadata
- Delete owned media after confirmation
- Download owned media using authentication
- Queue an idempotent background media job
- List own processing jobs
- Read an owned processing job
- Cancel an owned queued or running job
- Claim a queued job using the media-worker credential
- Download input for an authenticated leased job
- Download artwork for an authenticated leased job
- Upload output for an authenticated leased job
- Mark an authenticated leased job failed
- Unregister a device token by id or installation
- Register a Web Push subscription for the signed-in Clerk user
- Unregister a Web Push subscription
- Public VAPID key for browser PushManager.subscribe
- List notification topics
- List topics the current user is subscribed to
- Subscribe to a notification topic
- Unsubscribe from a notification topic
- Register iOS/Android FCM/APNs device token (apps alias)
- List own registered app devices (no raw tokens)
- Unregister device by installation_id or device_id
- Register iOS/Android device token for Blindbandit Mobile apps
- Unregister a Blindbandit Mobile app device
- Send a test notification to the current user devices
- Public LiveKit configuration status (no secrets)
- Mint a LiveKit room access token for the owner LiveKit server
- Social product liveness
- Official Spotify artist embeds for Music tab
- Search people and pages (profiles + handles)
- Newsfeed with optional filter (all|following|music)
- Publish a music/label-native feed post
- Explore public profiles
- Public social feed (optional following mode when signed in)
- Public profile by handle
- Posts for a public profile
- Current social profile (creates on first call)
- Create or ensure social profile
- Update social profile
- Create a public post (open to any Clerk account)
- Delete own post
- Edit own post body
- Follow a profile
- Unfollow a profile
- List conversations
- Send a direct message
- List messages in a conversation
- Start a voice or video call (LiveKit room)
- Join an existing call and receive a LiveKit token
- End a call
- Apply for profile verification
- Approve or reject verification (operator)
- Apply to creator monetization program
- List active marketplace ads
- Submit an ads marketplace listing
- Social admin dashboard counters
- Search and list social profiles with moderation state
- Permanently ban a social account
- Temporarily suspend a social account
- Unban or unsuspend a social account
- Mute posts/messages, disable calls, shadow-restrict, rate limits, feature flags
- Force-verify a profile
- Revoke verification badge
- Inspect redacted push devices for a profile
- Revoke all push tokens for a profile
- Force-end LiveKit calls for a profile
- Approve or reject monetization
- Verification review queue
- List content reports
- Resolve, dismiss, or escalate a report
- Hide a post from public feeds
- Unhide a post
- Admin-delete a post
- List pending ads marketplace listings
- Approve or reject an ads listing
- Create system announcement and notify recent users
- Social admin action audit log
- Admin test push to a profile id
- Unified role map for Mobile + Portal (same Clerk user)
- User Manager: list/search platform accounts (Clerk + roles)
- User Manager: user detail
- User Manager: assign role / enable / disable (affects Mobile + Portal)
- Backfill platform_accounts from social profiles
- List comments on a post
- Comment on a post
- Delete own comment
- Block a profile
- Unblock a profile
- In-app social notifications
- Mark social notifications read
- Creator program eligibility
- Creator earnings dashboard
- Creator earnings ledger
- List payout requests
- Request a payout from creator balance
- Start Stripe Checkout tip to a creator
- Settle a paid tip checkout session
- Approve/reject creator payout
- List label catalog releases
- Create a catalog release
- Update a catalog release
- React to a post (like/love/fire/laugh/wow/sad)
- Clear reaction on a post
- Like a post (alias of react=like)
- Unlike a post
- BanditBites vertical short-video feed
- Publish a BanditBite (fans and creators)
- Get one BanditBite
- Delete own BanditBite
- Increment BanditBite view count
- React to a BanditBite
- Clear BanditBite reaction
- List BanditBite comments
- Comment on a BanditBite
- Full profile with counts, links, privacy, bites count
- Profile posts grid
- Profile BanditBites tab
- Update full profile (bio, links, privacy, avatar URLs)
- Set avatar from uploaded media_id or avatar_url
- Set cover/banner from uploaded media_id or cover_url
- Trust & safety center payload
- File a trust & safety report (auth optional but preferred)
- List trust reports for moderators
- Appeal a moderation action
- Resolve/dismiss/escalate a trust report
- Bookmark a post
- Remove bookmark
- List bookmarked posts
- List post drafts
- Save a post draft
- Delete a draft
- Mute a profile (soft hide)
- Unmute a profile
- List followers
- List following
- Report a post, profile, or message
- Admin ops dashboard overview
- System settings
- Update system settings
- Role change history
- Record role change
- Trust & safety cases
- Create trust case
- Update trust case
- AdSense placements manager
- Update ad placement
- Planned infra leftovers (honest)
- Creator payouts queue
- Resolve creator payout
- Moderation bundle (reports/comments/bites/appeals)
- Platform audit log viewer
- Public subset of system settings (maintenance/signup)
- Pin post on profile
- Unpin profile pin
- Nested comment reply
- List nested replies
- Mentions inbox
- Hashtag feed
- Trending hashtags
- Mutual follow indicator
- List mute words
- Replace mute words
- Repost or quote
- Schedule a post
- List scheduled posts
- Publish due scheduled posts (cron/dev)
- Create poll on post
- Poll results
- Vote on poll
- Post analytics for author
- Record impression
- Close friends list
- Add close friend
- Remove close friend
- Active stories 24h
- Create story
- View story
- Create group chat
- List my groups
- Post group message
- List group messages
- DM read receipt
- Call history
- Share deep link
- Link unfurl card
- GIF picker catalog
- Translate post
- Profile extras (pronouns/theme/qr)
- Update profile extras
- Bite sounds library
- Bite effects filters
- Bite drafts
- Save bite draft
- Create duet link
- Create bite series
- Add bite to series
- Trending bites
- Editorial collections
- Genre pages
- Discovery rails
- Recommendations
- Trending topics alias
- Create live room
- Live rooms directory
- Live comment
- List live comments
- Live gift
- End live + recording hook
- Fan funding goals
- Create funding goal
- Merchandise shelf
- Add merch item
- Payout rails
- GDPR-style data export
- Account deletion request
- Log consent
- Brand safety categories
- Sponsored post label
- Webhook outbox
- Enqueue webhook
- Platform extension slots
- Get extension slot
- Configure extension slot
- Run extension handler
- Trust policy rules
- Spam heuristics
- Toxicity classifier hook
- Geo blocking list
- CSAM reporting pathway
- Notification channels
- Media format support
- CDN signed URL
- Virus scan hook
- Transcode job
- Minimal GraphQL-style query (capabilities|health)
- List planned capability stubs
- Accessibility WCAG 2.2 AA status